2015 CVE Vulnerabilities

8,779 CVEs published in 2015.

CVE IDSeverityCVSSDescription
CVE-2015-3406HIGH7.5The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SI...
CVE-2015-2060MEDIUM5.3cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers t...
CVE-2015-1855MEDIUM5.9verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x ...
CVE-2015-5155Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-3609. Reason: This candidate is a reservation du...
CVE-2015-9539MEDIUM6.1The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.
CVE-2015-9538MEDIUM6.5The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
CVE-2015-9537MEDIUM5.4The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_heig...
CVE-2015-4457MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated u...
CVE-2015-7831HIGH8.8In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
CVE-2015-6495HIGH7.5There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
CVE-2015-1396HIGH7.5A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files...
CVE-2015-7810MEDIUM4.7libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
CVE-2015-5694MEDIUM6.5Designate does not enforce the DNS protocol limit concerning record set sizes
CVE-2015-1780MEDIUM6.5oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
CVE-2015-3140HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Sy...
CVE-2015-2793MEDIUM6.1Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote at...
CVE-2015-3167HIGH7.5contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x be...
CVE-2015-3166CRITICAL9.8The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, a...
CVE-2015-1607MEDIUM5.5kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise...
CVE-2015-1606MEDIUM5.5The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a ...
CVE-2015-7276MEDIUM5.9Technicolor C2000T and C2100T uses hard-coded cryptographic keys.
CVE-2015-8980CRITICAL9.8The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbi...
CVE-2015-0270CRITICAL9.8Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
CVE-2015-9524MEDIUM6.1The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x be...
CVE-2015-9523MEDIUM6.1The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9....

Check if your code is affected by 2015 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now